v3.9.9
Released October 6, 2026
Makes token‑allocation administration more reliable and keeps automatic token top‑ups working up to each user’s configured limit.
Confirming this release. On the Token Distribution admin screen, saving an allocation policy now shows an on‑screen confirmation and flags invalid fields inline, and automatic token increases continue up to each user’s configured ceiling. Most changes here are administrative — if you don’t manage token allocation, confirm your deployment’s version with your Ask Sage administrator.
🔧 Improvements & fixes
- Automatic token top‑ups no longer stop early. Automatic increases could previously halt for an entire organization once internal safety buffers were reached, even while users were still below their configured ceiling. Those buffers are now advisory only — automatic increases continue up to each user’s configured ceiling, which remains the hard limit. Organizations without a purchased token pool for a given token type are unaffected.
- Clearer, safer allocation administration. The token‑allocation policy screen now validates each field as you enter it and won’t accept an invalid policy. Clearing a field no longer silently substitutes a default value or flips a ceiling to “unlimited,” and scrolling the mouse wheel over a number field no longer changes its value.
- Every action is confirmed on screen. Activating a policy, saving changes, or running a distribution now shows a clear confirmation — or an error — where you’re working, and each action is labeled for exactly what it does.
- One‑time distributions no longer alter your active policy. Running a one‑time token distribution no longer unintentionally changes an organization’s active allocation policy (for example, its floor).
🔒 Security & platform
- Stronger audit trail for token administration. Changes to allocation policies and to token grants, approvals, and denials are now recorded in the administrative audit log for review and export.
- Ask Sage services are delivered as FIPS‑hardened, digest‑pinned, and cosign‑signed images within the FedRAMP Class D authorization boundary, and are continuously rebuilt against the latest patched base images as part of Ask Sage’s continuous‑monitoring commitment.